Cover image of show Secure & Simple — Podcast for Consultants and CISOs on Cybersecurity Governance and Compliance

Secure & Simple — Podcast for Consultants and CISOs on Cybersecurity Governance and Compliance

Podcast by Dejan Kosutic

English

Technology & science

Limited Offer

1 month for 9 kr.

Then 99 kr. / monthCancel anytime.

  • 20 hours of audiobooks / month
  • Podcasts only on Podimo
  • All free podcasts
Get Started

About Secure & Simple — Podcast for Consultants and CISOs on Cybersecurity Governance and Compliance

“Secure & Simple” demystifies governance and compliance challenges faced by CISOs, consultants, and other cybersecurity professionals. The podcast is hosted by Dejan Kosutic, an expert in cybersecurity governance, ISO 27001, NIS2, and DORA. The episodes present topics in an easy-to-understand way and provide you with insight you won’t be able to find elsewhere. To provide comments, suggest topics for the next episodes, or express your interest in participating in the show, contact us at podcast@advisera.com. Learn more about ISO 27001, NIS2, and DORA at https://advisera.com.

All episodes

37 episodes

episode Why Conventional Cybersecurity Won’t Protect AI? | Interview with Hugo Huang artwork

Why Conventional Cybersecurity Won’t Protect AI? | Interview with Hugo Huang

In this Secure & Simple Podcast episode, host Dejan Kosutic (Advisera) talks with Hugo Huang, Product Director at Canonical and author of a Harvard Business Review article, about why conventional cybersecurity tools and patching alone are insufficient for AI systems. Huang shares research conducted with Canonical, IDC, and Google Cloud, highlighting leaders’ concerns about shadow AI usage, opaque and costly AI agents, and securing new hardware like GPUs, IPUs, and TPUs. They discuss AI-specific threats such as data poisoning, adversarial prompting, and model inversion attacks. Huang argues for hardening architecture with confidential computing (e.g., Intel TDX, AMD SEV, Nvidia H100) and for managerial changes, including CEO-level ownership, HR planning for scarce AI-security talent, supplier strategy to avoid vendor lock-in, and using frameworks like NIST’s AI risk management framework to guide policies and governance. Links from the episode: - Conformio software to streamline and scale ISO 27001 implementation and maintenance for your clients: https://advisera.co/Conformio-software [https://advisera.co/Conformio-software] - White label documentation toolkits for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: https://advisera.co/page-all-toolkits [https://advisera.co/page-all-toolkits] - Accredited Lead Auditor and Lead Implementer courses for various standards and frameworks to show your expertise to potential clients: https://advisera.co/Consultant-Courses [https://advisera.co/Consultant-Courses] - Company Training Academy with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: https://advisera.co/page-Company-Training-Account [https://advisera.co/page-Company-Training-Account]  - Beginner's Course for ISO, Cybersecurity, and AI Consultants: https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t [https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t] - How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:https://advisera.co/GrowYourConsultancyTraining [https://advisera.co/GrowYourConsultancyTraining]  * (00:00) - Interview with Hugo Huang * (04:34) - Three Executive Fears * (07:58) - New AI Attack Types * (11:59) - Patching Is Not Enough * (14:33) - Confidential Computing Basics * (17:00) - TPUs Market Shift * (19:46) - Management Must Change * (28:26) - Security Protects Brand * (33:34) - Suppliers Vendor Lock-in * (41:31) - Advisera Resources

16 Jun 2026 - 42 min
episode ISO 27001 Certification: What Will the Auditor Look For? | Interview with Aron Lange artwork

ISO 27001 Certification: What Will the Auditor Look For? | Interview with Aron Lange

In this Secure & Simple Podcast episode, host Dejan Kosutic (CEO of Advisera) interviews Aron Lange, founder of GRC Lab and an ISO 27001 certification auditor, about what auditors look for in certification audits. Aron highlights common nonconformities and explains how auditors gather objective evidence through interviews, document review, and observation, emphasizing execution over paperwork. The conversation also covers auditor interpretation, challenging unsupported findings, risk-based control auditing, management-system vs security-posture certification, continual improvement, and the difference between nonconformities and opportunities for improvement. Links from the episode: - Conformio software to streamline and scale ISO 27001 implementation and maintenance for your clients: https://advisera.co/Conformio-software [https://advisera.co/Conformio-software] - White label documentation toolkits for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: https://advisera.co/page-all-toolkits [https://advisera.co/page-all-toolkits] - Accredited Lead Auditor and Lead Implementer courses for various standards and frameworks to show your expertise to potential clients: https://advisera.co/Consultant-Courses [https://advisera.co/Consultant-Courses] - Company Training Academy with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: https://advisera.co/page-Company-Training-Account [https://advisera.co/page-Company-Training-Account]  - Beginner's Course for ISO, Cybersecurity, and AI Consultants: https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t [https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t] - How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:https://advisera.co/GrowYourConsultancyTraining [https://advisera.co/GrowYourConsultancyTraining]  * (00:00) - Interview with Aron Lange * (01:09) - Top Nonconformities in Audits * (04:20) - How Auditors Gather Evidence * (11:55) - The Limits of Tools Based on SOC 2 * (14:05) - Challenging Auditor Interpretations * (16:48) - Disputing Nonconformities * (19:38) - Problem with Generic Controls * (23:07) - Certifying Management System * (27:02) - Nonconformity vs Improvement * (29:58) - Auditing vs Consulting * (32:24) - Auditor Mindset and Trust * (35:03) - Prep Tips and Wrap Up * (36:30) - Resources for Consultants and CISOs

2 Jun 2026 - 37 min
episode Anthropic’s Mythos and the Future of Vulnerability Management | Interview with Thom Langford artwork

Anthropic’s Mythos and the Future of Vulnerability Management | Interview with Thom Langford

In this Secure and Simple Podcast episode, host Dejan Kosutic (CEO at Advisera) speaks with Thom Langford, CTO for the EMEA region at Rapid7, about Anthropic’s new AI model “Mythos” and its impact on cybersecurity. Langford argues that the fundamentals remain the same - discover, risk-contextualize, and patch - but the speed, scale, and volume of findings will surge, exposing immature vulnerability and patch-management programs. They explore continuous vulnerability monitoring tied to the SDLC, potential increases in breaches for less-prepared organizations, governance and arms-race concerns, changes to CISO scrutiny and responsibilities (including AI governance), impacts on budgets, and resilience as a differentiator. Links from the episode: - Conformio software to streamline and scale ISO 27001 implementation and maintenance for your clients: https://advisera.co/Conformio-software [https://advisera.co/Conformio-software] - White label documentation toolkits for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: https://advisera.co/page-all-toolkits [https://advisera.co/page-all-toolkits] - Accredited Lead Auditor and Lead Implementer courses for various standards and frameworks to show your expertise to potential clients: https://advisera.co/Consultant-Courses [https://advisera.co/Consultant-Courses] - Company Training Academy with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: https://advisera.co/page-Company-Training-Account [https://advisera.co/page-Company-Training-Account]  - Beginner's Course for ISO, Cybersecurity, and AI Consultants: https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t [https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t] - How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:https://advisera.co/GrowYourConsultancyTraining [https://advisera.co/GrowYourConsultancyTraining]  * (00:00) - Interview with Thom Langford * (01:01) - Mythos Hype or Reality? * (04:42) - Speed Scale and Patch Basics * (06:48) - Maturity Gap and Risk Context * (10:16) - Continuous Exposure Management * (12:19) - Unprepared Firms and Breach Risk * (14:43) - Release Governance and Arms Race * (18:29) - CISO Role Under Scrutiny * (27:36) - Strategy, Budgets, and Resilience * (33:49) - Industry Shifts and Human Loop * (38:08) - CISO Prep Recommendations * (40:04) - Resources for CISOs and Consultants

19 May 2026 - 41 min
episode What CISOs Must Do Now About Quantum? | Interview with Andrew Gault artwork

What CISOs Must Do Now About Quantum? | Interview with Andrew Gault

In this Secure and Simple Podcast episode, host Dejan Kosutic (CEO of Advisera) interviews Andrew Gault (CEO of ZeroTier) about how quantum computing could impact cybersecurity, especially encryption and identity. They explain key terms like post-quantum cryptography (PQC), Q-Day, cryptographically relevant quantum computers, and main threats, “harvest now, decrypt later” and “trust now, forge later.” Andrew outlines shifting timelines, citing U.S. CNSA 2.0 requiring quantum-resistant cryptography for new acquisitions after Jan 1, 2027, and broader conversion targets around 2029–2030, plus EU guidance aiming for critical sectors to be quantum resistant by ~2030 and others by 2035. They note PQC algorithms are standardized (e.g., NIST FIPS 203, ML-KEM), but the challenge is operational: inventory systems (“quantum bill of materials”), prioritize crown jewels, engage vendors, budget, and manage upgrades or mitigations for legacy systems, potentially using overlay networks. Links from the episode: - Conformio software to streamline and scale ISO 27001 implementation and maintenance for your clients: https://advisera.co/Conformio-software [https://advisera.co/Conformio-software] - White label documentation toolkits for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: https://advisera.co/page-all-toolkits [https://advisera.co/page-all-toolkits] - Accredited Lead Auditor and Lead Implementer courses for various standards and frameworks to show your expertise to potential clients: https://advisera.co/Consultant-Courses [https://advisera.co/Consultant-Courses] - Company Training Academy with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: https://advisera.co/page-Company-Training-Account [https://advisera.co/page-Company-Training-Account]  - Beginner's Course for ISO, Cybersecurity, and AI Consultants: https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t [https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t] - How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:https://advisera.co/GrowYourConsultancyTraining [https://advisera.co/GrowYourConsultancyTraining]  * (00:00) - Interview with Andrew Gault * (01:14) - Why Quantum Matters * (04:05) - Quantum Terms Explained * (06:05) - When Q Day Hits * (07:00) - Deadlines and Industry Shifts * (11:34) - NIST Approved Algorithms * (14:35) - New Threat Models * (16:34) - Why Companies Delay * (20:30) - Quantum Bill of Materials * (23:08) - Executive Priorities * (28:49) - Vendor Roadmaps * (30:31) - Customer Messaging Strategy * (34:02) - CISO Role and Influence * (35:37) - Modernization Opportunity * (38:59) - Consulting Market Opportunity * (40:47) - Action Plan and Wrap Up * (42:23) - Resources for Consultants and CISOs

5 May 2026 - 43 min
episode Continual Improvement, Nonconformities, and Corrective Actions | Interview with Carlos Cruz artwork

Continual Improvement, Nonconformities, and Corrective Actions | Interview with Carlos Cruz

In this Secure and Simple Podcast episode, host Dejan Kosutic from Advisera interviews Carlos Cruz, founder of Metanoia and an ISO 9001/ISO 14001 expert, about continual improvement in ISO standards and how the concepts apply to cybersecurity. They explain continual improvement through the PDCA cycle, using data and Pareto analysis to focus on key issues, then performing root cause analysis with tools like the fishbone (Ishikawa) diagram and the 5 Whys to avoid stopping at “human error.” They define nonconformities, clarify the difference between corrections (e.g., restoring operations) and corrective actions (i.e., removing root causes to prevent recurrence), and discuss when root cause analysis is warranted, including high-impact or recurring cybersecurity incidents. They also cover documenting and tracking nonconformities via approaches like ticketing systems, consultant do’s and don’ts, and practical ways to motivate management by translating issues into business impact. Links from the episode: - Conformio software to streamline and scale ISO 27001 implementation and maintenance for your clients: https://advisera.co/Conformio-software [https://advisera.co/Conformio-software] - White label documentation toolkits for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: https://advisera.co/page-all-toolkits [https://advisera.co/page-all-toolkits] - Accredited Lead Auditor and Lead Implementer courses for various standards and frameworks to show your expertise to potential clients: https://advisera.co/Consultant-Courses [https://advisera.co/Consultant-Courses] - Company Training Academy with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: https://advisera.co/page-Company-Training-Account [https://advisera.co/page-Company-Training-Account]  - Beginner's Course for ISO, Cybersecurity, and AI Consultants: https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t [https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t] - How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:https://advisera.co/GrowYourConsultancyTraining [https://advisera.co/GrowYourConsultancyTraining]  * (00:00) - Interview with Carlos Cruz on continual improvement * (01:27) - PDCA and Continual Improvement * (05:52) - Improvement Beyond Problems * (08:22) - Nonconformities Explained * (11:47) - When to Do Root Cause Analysis * (15:19) - Pareto and Fishbone Methods * (17:39) - Using the Five Whys Method * (21:27) - Building Root Cause Culture * (25:00) - Who Reports Nonconformities * (29:27) - Corrections vs Corrective Actions * (34:25) - Documenting Without Bureaucracy * (40:32) - Consultants Do and Don'ts * (47:02) - Selling Improvement to Management * (50:00) - Top Tips for Continual Improvement * (54:39) - Resources for Consultants and Security Officers

21 Apr 2026 - 56 min
En fantastisk app med et enormt stort udvalg af spændende podcasts. Podimo formår virkelig at lave godt indhold, der takler de lidt mere svære emner. At der så også er lydbøger oveni til en billig pris, gør at det er blevet min favorit app.
En fantastisk app med et enormt stort udvalg af spændende podcasts. Podimo formår virkelig at lave godt indhold, der takler de lidt mere svære emner. At der så også er lydbøger oveni til en billig pris, gør at det er blevet min favorit app.
Rigtig god tjeneste med gode eksklusive podcasts og derudover et kæmpe udvalg af podcasts og lydbøger. Kan varmt anbefales, om ikke andet så udelukkende pga Dårligdommerne, Klovn podcast, Hakkedrengene og Han duo 😁 👍
Podimo er blevet uundværlig! Til lange bilture, hverdagen, rengøringen og i det hele taget, når man trænger til lidt adspredelse.

Choose your subscription

Most popular

Limited Offer

Premium

20 hours of audiobooks

  • Podcasts only on Podimo

  • No ads in Podimo shows

  • Cancel anytime

1 month for 9 kr.
Then 99 kr. / month

Get Started

Premium Plus

Unlimited audiobooks

  • Podcasts only on Podimo

  • No ads in Podimo shows

  • Cancel anytime

Start 30 days free trial
Then 129 kr. / month

Start for free

Only on Podimo

Popular audiobooks

Get Started

1 month for 9 kr. Then 99 kr. / month. Cancel anytime.